|
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [PATCH 1/2] tools/symbols: reject names exceeding the runtime limit
The symbol generator accepts names longer than the runtime lookup
buffers, which hold KSYM_NAME_LEN + 1 bytes. SYSV input prefixes local
symbols with their filename, so an absolute assembly source path can
produce an oversized name even when the symbol itself is short.
This caused a debug Xen boot to crash on an Orange Pi 5. The expanded
name ending in mmu/head.S#identity_mapping_removed was 145 bytes long.
During the test_symbols() constructor (CONFIG_SELF_TESTS),
symbols_lookup_by_name() expanded it into a 128-byte buffer and
overwrote the saved frame pointer and return address.
The board reported:
(XEN) [ 5.064767] Hypervisor Trap. HSR=0x0000008a000000 EC=0x22 IL=1
Syndrome=0x0
(XEN) [ 5.066709] PC: 65766f6d65725f67 65766f6d65725f67
(XEN) [ 5.067190] LR: 65766f6d65725f67
(XEN) [ 5.074749] X27: 0000000000000000 X28: 0000000049000000 FP:
6e697070616d5f79
The FP and LR values decode to "y_mappin" and "g_remove", respectively,
matching bytes 128 through 143 of the expanded name.
Reject retained names exceeding the existing KSYM_NAME_LEN limit before
compression. Report the offending name and its byte length, so that the
build fails with, for example (name shortened here)::
Symbol '...#compatibility_mode' is too long (128 bytes, maximum 127)
A build from a very long absolute source path now stops at link time,
instead of producing an image with a latent overflow. Apply the check
after symbol filtering and preserve unrestricted human-readable
--xensyms maps.
Fixes: d37d63d4b548 ("symbols: prefix static symbols with their source file
names")
Assisted-by: Codex:GPT-6.1
Assisted-by: Copilot:claude-sonnet-5.5 # host and x86 build tests
Signed-off-by: Mykola Kvach <mykola_kvach@xxxxxxxx>
---
xen/tools/symbols.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/xen/tools/symbols.c b/xen/tools/symbols.c
index 9db1c0a20c..e15273a8ad 100644
--- a/xen/tools/symbols.c
+++ b/xen/tools/symbols.c
@@ -485,6 +485,13 @@ static void build_initial_tok_table(void)
pos = 0;
for (i = 0; i < table_cnt; i++) {
if ( symbol_valid(&table[i]) ) {
+ if (!map_only && table[i].len > KSYM_NAME_LEN + 1) {
+ fprintf(stderr,
+ "Symbol '%s' is too long (%u bytes,
maximum %u)\n",
+ SYMBOL_NAME(&table[i]), table[i].len -
1,
+ KSYM_NAME_LEN);
+ exit(1);
+ }
if (pos != i)
table[pos] = table[i];
learn_symbol(table[pos].sym, table[pos].len);
--
2.53.0
|
![]() |
Lists.xenproject.org is hosted with RackSpace, monitoring our |